CVE-2024-56344: IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities
IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Other sources
IBM Cognos Analytics could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.0.4 FP3 - Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 12.1.3 FP2 - Configuration
Enable HTTP Strict Transport Security (HSTS) in IBM Cognos Analytics to address the issue where HTTP Strict Transport Security was not properly enabled (affected ranges: 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1).
IBM Cognos Analytics HTTP Strict Transport Security (HSTS) = Properly enable HSTS - Compensating control
Use a network-layer man-in-the-middle mitigation (e.g., enforce HTTPS with strong certificate validation and/or restrict access paths so attackers cannot intercept connections) until the fixed IBM Cognos Analytics releases (12.0.4 FP3, 12.1.3 FP2) are applied.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM Cognos Analytics 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1.
What does an attacker need to exploit this issue?
An attacker must be able to conduct a man-in-the-middle attack against traffic to the affected Cognos Analytics deployment. No privileges or user interaction are required, but the attack complexity is high.
What is the potential impact?
A successful attacker could obtain sensitive information from affected communications. The provided impact information identifies confidentiality impact, with no integrity or availability impact.